Jenkins Security Advisory 2026-08-05
Affects Jenkins Core Affects plugin: AWS CodeBuild Affects plugin: CodeSonar Affects plugin: External Workspace Manager Affects plugin: Google Chat Notification Affects plugin: HCL AppScan Affects plugin: Horreum Affects plugin: Ivy Report Affects plugin: Multijob Affects plugin: Parameterized Remote Trigger Affects plugin: Qualys Container Scanning Connector Affects plugin: Sauce OnDemand Affects plugin: SCM-Manager Affects plugin: Summary Display Affects plugin: Violation Comments to GitLab Affects plugin: Webhook Secret Credentials Provider Affects plugin: XML Job to Job DSL
CSIRTS triage
- What
- Multiple unspecified vulnerabilities affect Jenkins Core and 15 associated plugins.
- Who is affected
- Deployments of Jenkins Core and users of AWS CodeBuild, CodeSonar, External Workspace Manager, Google Chat Notification, HCL AppScan, Horreum, Ivy Report, Multijob, Parameterized Remote Trigger, Qualys Container Scanning Connector, Sauce OnDemand, SCM-Manager, Summary Display, Violation Comments to GitLab, and Webhook Secret Credentials Provider plugins.
- Urgency
- Severity unknown; eight CVEs assigned indicate multiple impact vectors requiring immediate investigation.
- Action
- Consult Jenkins Security Advisory 2026-08-05 for specific vulnerability details and apply recommended patches for Core and affected plugins.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins Core and multiple plugins
Get an email when a new Jenkins Core and multiple plugins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.jenkins.io/security/advisory/2026-08-05/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-704260.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704270.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704280.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704290.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704300.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704310.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704320.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704330.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704340.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704350.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Jenkins Plugins: Multiple vulnerabilitiescert-bund
- unknownJenkins Multiple Vulnerabilitieshkcert
- highCVE-2026-70448: Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML ext…nvd
- mediumCVE-2026-70447: Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers wit…nvd
- mediumCVE-2026-70446: Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with O…nvd
- mediumCVE-2026-70445: Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers w…nvd
- mediumCVE-2026-70444: A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier a…nvd
- mediumCVE-2026-70443: Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate con…nvd
- mediumCVE-2026-70442: Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the approp…nvd
- mediumCVE-2026-70441: Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript c…nvd
- mediumCVE-2026-70440: Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-co…nvd
- mediumCVE-2026-70439: Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allow…nvd
More from Jenkins Security Advisories
- unknownJenkins Security Advisory 2026-06-242026-06-24
- unknownJenkins Security Advisory 2026-06-102026-06-10
- unknownJenkins Security Advisory 2026-05-272026-05-27
- unknownJenkins Security Advisory 2026-04-292026-04-29
- unknownJenkins Security Advisory 2026-03-182026-03-18